Correct Answer: D
Explanation/Reference:
Explanation:
A smart card, which includes the ability to process data stored on it, is also able to deliver a two-factor authentication method as the user may have to enter a PIN to unlock the smart card. The authentication can be completed by using an OTP, by utilizing a challenge/response value, or by presenting the user's private key if it is used within a PKI environment. The fact that the memory of a smart card is not readable until the correct PIN is entered, as well as the complexity of the smart token makes these cards resistant to reverse-engineering and tampering methods.
Incorrect Answers:
A: Transparent renewal of user keys is not the primary role of smartcards in a PKI.
B: Easy distribution of the certificates between the users is not the primary role of smartcards in a PKI.
C: Fast hardware encryption of the raw data is not the primary role of smartcards in a PKI.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 200, 201
http://en.wikipedia.org/wiki/Tamper_resistance